Database Security Products (MOSC)

MOSC Banner

Need help for environement Security with RAC system

edited Jul 16, 2019 8:22AM in Database Security Products (MOSC) 2 commentsAnswered

Hello  ,

My environment :

O.S: Oracle Linux Server release 6.5

Grid:11.2.0.4

D.B:11.2.0.4

RAC system 2 node.

Our company make a security assessment and this is the O.S Recommendations Actions:

1-The vulnerability allows a remote attacker to enumerate all accounts on the system. The vulnerability exists due to a logical error in auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c files when processing authentication requests. A remote attacker can send a specially crafted chain of packets and monitor behavior of openssh server to determine presence of a valid username. The server will drop connection upon receiving a malformed authentication packets if the username is valid.

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center